{
  "$schema": "http://cyclonedx.org/schema/bom-1.6.schema.json",
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "serialNumber": "urn:uuid:8d640ff9-364d-5bb2-b702-64a021f09684",
  "version": 1,
  "metadata": {
    "supplier": {
      "name": "TuxCare",
      "url": [
        "https://tuxcare.com"
      ]
    }
  },
  "components": [
    {
      "name": "spring-instrument",
      "purl": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1",
      "type": "library",
      "group": "org.springframework",
      "bom-ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1",
      "version": "5.2.10.RELEASE-tuxcare.1",
      "supplier": {
        "url": [
          "https://tuxcare.com"
        ],
        "name": "TuxCare"
      }
    }
  ],
  "vulnerabilities": [
    {
      "id": "CVE-2016-1000027",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:695c4b3d-f556-5d88-9099-61ce6816fc92",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2016-1000027 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument and will not be fixed. It is not a patchable flaw but an inherent risk of Java serialization. It is recommended not exposing HTTP Invoker endpoints to untrusted clients; if such exposure is absent, no further action is required",
        "response": [
          "will_not_fix"
        ]
      }
    },
    {
      "id": "CVE-2021-22060",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:386bb746-35b3-55ed-955c-7c28aa7e5dd8",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22060 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22096",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2b88e6eb-7246-5c62-ae90-7adf94933c9a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22096 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2021-22118",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:2e4e88d9-454e-5d1d-abd3-32fd53178fbd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2021-22118 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22950",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36a5ce7d-4b75-59c0-80a2-48bb1a1a90f8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22950 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22965",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:34682efa-214b-54a9-af9c-977cb30865ed",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2022-22965 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22968",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:4505509a-07ed-5762-828a-d02ad6e7a249",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22968 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22970",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7720e565-0570-5c9b-ab87-a369f7471b6c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22970 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2022-22971",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d49136a0-ae25-5d10-be0b-ab75ad7ceecc",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2022-22971 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20861",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9a4c8e8d-30bf-5ba5-972e-393a9d78334e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20861 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2023-20863",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c19fbfd9-7334-5a1c-80cb-294f4d419380",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2023-20863 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22243",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:b409d4c4-b8ec-58f5-89e9-6938fa28da35",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22243 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22259",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:979abca0-4404-5f6a-a3b6-c928bacc5f01",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22259 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-22262",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:05c5418e-f24e-5896-920d-07607555b8a5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-22262 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38808",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:23a4d400-8c63-5225-8c07-0a25d4975877",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2024-38808 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38809",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e10c128-03b6-501b-8657-b3ce9f6d5393",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38809 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38816",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:403680da-a5d4-524b-a230-fc777a6b0ea6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38816 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38819",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:36a7e85b-7b6f-52ff-a2b2-825e13a9565a",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2024-38819 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2024-38820",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:12f96546-0e00-5508-9191-c2c8faabc12d",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2024-38820 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument. not_affected \u2014 Version 5.2.10.RELEASE does not contain the vulnerable code pattern described in CVE-2024-38820. This CVE specifically affects the fix for CVE-2022-22968, which introduced case-insensitive field matching using String.toLowerCase() without a Locale parameter. The target version uses case-sensitive matching and does not call toLowerCase() in its DataBinder field validation logic. Therefore, the l...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2025-22233",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1b11002a-9181-5f0a-addb-ce03861a25b4",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-22233 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41242",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:0e138491-46b2-5f10-92fe-29eacb76facc",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41242 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41249",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:62f7f853-c621-5cfd-a253-bc7ed41a354c",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2025-41249 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2025-41254",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:44ece53e-df25-565b-8d94-d2303ce88e85",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2025-41254 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22735",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69e17fee-429a-5e45-b788-66c039280978",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22735 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22737",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:656433b6-74ec-5c5a-bf46-4e81afe0d004",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22737 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22740",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fb048ab4-47c1-5226-9a95-5aed4d70e994",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-22740 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22741",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:38111eea-ac4e-582a-8928-3a252aeface4",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22741 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-22745",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:7e47288a-54d7-59e9-8314-2c318bb448c6",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-22745 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41838",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:dd7a6df0-f4ce-5be9-8f61-c7e054db87ec",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41838 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41839",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:5568c8be-0b17-572a-b603-c98542a5a78e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41839 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41840",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:69544435-b117-5702-89cf-419b86dcf425",
      "analysis": {
        "state": "not_affected",
        "detail": "Vulnerability CVE-2026-41840 does not affect version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument. not_affected \u2014 Version 5.2.10.RELEASE is not affected by CVE-2026-41840. The vulnerability targets the PartGenerator/MultipartParser multipart parsing implementation introduced in Spring Framework 5.3.0. Version 5.2.10 (released October 2020, before 5.3.0) uses a completely different Synchronoss-based multipart parsing architecture that does not have the vulnerable BodyToken buffering mechanism. The vulnerabl...",
        "justification": "code_not_present"
      }
    },
    {
      "id": "CVE-2026-41841",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:552a4f72-f03a-5b54-9e8e-87068a7f0989",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41841 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41842",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:75f03662-0ec1-5ea8-95f7-115f61864f33",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41842 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41843",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:15a18e97-4886-5b56-b289-9aabcf484fc5",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41843 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41844",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c7bf7155-c241-5a89-8fe6-0a577520404a",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41844 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41845",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:fe601b7d-a5bf-5dcb-9b72-539efd031adb",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41845 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41846",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:c0f88a1f-c6f2-5cd8-aa98-bb7f8c599d5f",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41846 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41847",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:db25d6f1-7b8d-5acb-936c-add117ac8c79",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41847 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41848",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:f6b3ef10-f52c-5876-becc-9d34e021afdd",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41848 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41849",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:3b7c24da-1061-52d2-9247-7969cb181ff8",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41849 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41850",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:605929eb-5072-530b-9b7e-267ed37cc542",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41850 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41851",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d69ace06-5403-58b0-a90d-972fe0cce5ab",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41851 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41852",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a9c0e687-90e4-5cd8-aa49-ecb46d235b93",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41852 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41853",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45db5632-8017-5919-b236-f068f7bdfe4e",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41853 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41854",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:d2871802-da6e-522a-9818-bc1c46bcb52b",
      "analysis": {
        "state": "exploitable",
        "detail": "Vulnerability CVE-2026-41854 affects version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-41855",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:e47789d8-fd9b-5a51-85d0-f8bb069b1ecf",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-41855 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47884",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:bff94ec2-388d-5e69-87c6-f46ef32f0938",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47884 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47886",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:9e7ab324-cea9-5da9-a305-54d9cfd9978b",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47886 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47887",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:65faf07b-de1e-5104-9ef5-02245ad54a5d",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47887 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47888",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:523c5800-a68e-56d2-8be7-079e7e962590",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47888 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47891",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:45d444c2-4789-5add-9928-a30aa753d0a9",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47891 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47892",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:694330b7-42eb-5120-8198-7c76885b9087",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47892 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-47893",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:a0d33d1a-5990-5f4c-a34f-11fe3a5a1bc1",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-47893 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59280",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:8ffbb77e-302b-5676-90bc-8158c64ae98e",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59280 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59281",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:19c7f1fb-db4e-5e9f-8449-f7924c30619c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59281 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59282",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:461211f5-f855-55f4-861c-abfeb73ad0cd",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59282 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59283",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:1ea7d87f-57d9-5346-b434-bd4f26d4d755",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59283 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    },
    {
      "id": "CVE-2026-59314",
      "affects": [
        {
          "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
        }
      ],
      "bom-ref": "urn:uuid:55e769f9-0bd5-5ccf-bf33-b50ebb4db01c",
      "analysis": {
        "state": "resolved",
        "detail": "Vulnerability CVE-2026-59314 is fixed in version 5.2.10.RELEASE-tuxcare.1 of org.springframework:spring-instrument."
      }
    }
  ],
  "dependencies": [
    {
      "ref": "pkg:maven/org.springframework/spring-instrument@5.2.10.RELEASE-tuxcare.1"
    }
  ]
}